CVE-2026-13693 PUBLISHED

Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal

Assigner: WPScan
Reserved: 29.06.2026 Published: 21.07.2026 Updated: 21.07.2026

The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.

Product Status

Vendor Unknown
Product Bit Form
Versions Default: unaffected
  • affected from 0 to 3.1.0 (excl.)

Credits

  • Davud Sahibzada finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE